DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Thousands of servers can be backdoored by exploiting buggy motherboard controllers

Quality: 9/10 Relevance: 9/10

Summary

Ars Technica reports that baseboard management controllers (BMCs) in enterprise servers contain numerous vulnerabilities across vendors, exposing thousands of servers to remote backdoors. Research by HD Moore and runZero shows more than 86,000 externally exposed BMCs with one or more critical vulnerabilities, including CVE-2013-4786, and nearly 29% of internal BMCs surveyed had critical flaws. The piece outlines bug classes such as IPMI authentication handshake flaws, in-session integrity issues, predictable session IDs, pre-auth memory corruptions, unsigned firmware, and factory-default credentials, and notes attacks like ILObleed and a new tool OOBscan for fleet-wide scanning with mitigations including strong credentials, disabling IPMI, isolating BMC networks, and patching firmware.

🚀 Service construit par Johan Denoyer